Skip to content
Discussion options

You must be logged in to vote

@yangkaa trivy only report on found matching Cves to vulnerable components. if a component is not vulnerable and has no match to CVes it. not be reported by trivy.

it behave different from ConfigAudit in that sense

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@yangkaa
Comment options

@chen-keinan
Comment options

@yangkaa
Comment options

@chen-keinan
Comment options

Answer selected by yangkaa
@yangkaa
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants